SC-200 Perform threat hunting Practice Question
Which THREE of the following are key components of a successful threat hunting program in a Microsoft Defender XDR environment?
⚠ Common exam trap
SC-200 often tests the distinction between proactive threat hunting (hypothesis, MITRE ATT&CK, baselining) and reactive incident response (playbooks, alert triage), tempting candidates to select automation options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deep understanding of normal network behavior
A successful threat hunting program in Microsoft Defender XDR requires a deep understanding of normal network behavior (A), because establishing a baseline of legitimate activity lets hunters spot anomalies across endpoint, identity, email, and cloud telemetry that automated detections may miss. A clear hypothesis based on threat intelligence (B) is essential, since threat hunting is hypothesis-driven rather than alert-driven; hunters use intel to form testable assumptions about adversary behavior and then query Defender XDR advanced hunting (KQL) to validate or refute them. The use of the MITRE ATT&CK framework (C) is also a key component, as it maps observed techniques and tactics to a common taxonomy, helping hunters prioritize coverage gaps and structure hunts around known adversary TTPs. Automated incident response playbooks (D) belong to SOAR/automated investigation and response, not threat hunting, and reactive response to alerts (E) is the opposite of proactive hunting, so neither is a core component of a threat hunting program.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deep understanding of normal network behavior
Why this is correct
Baselining normal network behaviour lets hunters spot anomalies such as beaconing, unusual lateral movement or data staging in Defender XDR telemetry. Without knowing what routine traffic looks like, distinguishing genuine malicious activity from benign administrative patterns is impossible, so this underpins every hypothesis.
- ✓
A clear hypothesis based on threat intelligence
Why this is correct
A hypothesis directs hunting rather than aimless querying. Deriving it from threat intelligence about actors targeting your sector focuses advanced hunting queries in Microsoft Defender XDR on specific TTPs, making detection of otherwise invisible activity far more likely within limited analyst time.
- ✓
Use of MITRE ATT&CK framework
Why this is correct
MITRE ATT&CK maps adversary tactics and techniques to concrete hunting queries, ensuring coverage gaps are identified rather than assumed. It gives Microsoft Defender XDR hunters a shared vocabulary and structured progression through the kill chain, preventing over-focus on a single technique.
- ✗
Automated incident response playbooks
Why it's wrong here
Automated incident response playbooks execute containment after detections fire; threat hunting is a hypothesis-driven, proactive search for undetected activity, so playbooks sit outside its components. They are tempting because automation is central to broader Defender XDR operations, where they are the right choice for response orchestration.
- ✗
Reactive response to alerts
Why it's wrong here
Reacting to alerts is detection-and-response, not hunting, which proactively searches for threats that generated no alert. It is tempting because alert triage is essential security operations work, and reactive handling is the correct approach for a question about incident response processes.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.